Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-18316: Solace Extra <= 1.6.0 - Unauthorized Site Content Deletion
CVE-2026-18316 · published 19 days ago
Summary
The Solace Extra plugin for WordPress has a security issue that allows attackers with a low-level account to delete important site content and settings. This could cause significant data loss and disrupt your website. Update to the latest version of Solace Extra to fix this issue.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| solacewp | solace extra | <= 1.6.0 |
Original advisory text
Solace Extra <= 1.6.0 - Missing Authorization to Unauthenticated Site Content Deletion and Unauthorized Demo Import via action-import-zip AJAX Action
The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to, and including, 1.6.0. The handler is registered on both wp_ajax_action-import-zip and wp_ajax_nopriv_action-import-zip and only verifies the 'ajax-nonce' nonce, which is emitted on every admin page via wp_localize_script (unrestricted admin_enqueue_scripts hook) and is therefore accessible to any authenticated user including Subscribers. This makes it possible for authenticated attackers, with Subscriber-level access and above, to wipe navigation menus, sidebar widgets (via update_option('sidebars_widgets', array())), all theme mods (via remove_theme_mods()), and Elementor templates, as well as trigger arbitrary demo-content imports.
References
- https://www.wordfence.com/threat-intel/vulnerabilities/id/4e427c4e-3e27-49e3-ba6...
- https://plugins.trac.wordpress.org/browser/solace-extra/tags/1.6.0/admin/import....
- https://plugins.trac.wordpress.org/browser/solace-extra/tags/1.6.0/includes/clas...
- https://plugins.trac.wordpress.org/browser/solace-extra/tags/1.6.0/admin/class-s...
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3627961%40solace-extr...
Severity
9.1
Critical
CVSS 3.1: 9.1 (MITRE)
Exploitation
EPSS <1%
Type
CWE-862Missing Authorization
Timeline
Published16 Aug 2026
Updated30 Aug 2026
First seen16 Aug 2026
Monitor software like this
Free during beta